I will do penetration testing of your website and web application with a full report

Greece

I speak Ukrainian, Russian, English

Full Stack Developer and Security Engineer

I build products, and then I try to break them. That combination is why clients keep me around after launch. Years of production software: React and Vue on the front, Python and Node behind them, Pos...
About this Gig

You need an external security assessment, and a report you can hand to a client, an investor or an auditor.


WHAT I TEST

 - OWASP Top 10, tested by hand and not only by a scanner

 - Authentication, sessions, password reset, and the ways around them

 - Access control: whether user A can reach user B's data by changing a number

 - Business logic: sequences of legitimate actions that produce an illegitimate result

 - APIs, including the endpoints your interface never calls

 - Website security configuration: headers, cookies, transport, exposed services


WHAT YOU GET

A report in two layers. An executive summary a non technical person can act on, and a technical section with reproduction steps, evidence and a concrete fix for every finding. Findings are ranked by real risk to your business, not by scanner severity.


RULES I WORK BY

Written authorization from the system owner before anything starts. Agreed scope and agreed testing window. No production data touched, no destructive testing, no denial of service. If you cannot authorize the target, I cannot take the job.


Message me with the target and your timeline and I will tell you what is realistic.


Testing application:

Web application

Development technology:

JavaScript

•

NoSQL

•

Python

•

SQL

•

TypeScript

Device:

PC

•

Mac

•

Linux

•

iPhone

•

Android mobile phone

My Portfolio